Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-312

MITRE ↗

CWE-312

16
CRITICAL
61
HIGH
95
MEDIUM
12
LOW
196 CVEs · Page 2/4
6.5
CVE-2026-66781

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv

6.1
CVE-2026-7163

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul

5.8
CVE-2026-24319

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin

5.7
CVE-2025-47147

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow

5.7
CVE-2026-5224

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade I

5.6
CVE-2026-24311

The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational d

5.5
CVE-2026-22276

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage

5.5
CVE-2026-43942

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior,

5.5
CVE-2026-34490

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac

5.5
CVE-2026-61928

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

5.5
CVE-2026-73834

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper

5.5
CVE-2026-82640

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or

5.3
CVE-2026-5531

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o

4.9
CVE-2025-12680

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di

4.9
CVE-2025-12772

Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM

4.9
CVE-2026-3221

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which

4.7
CVE-2026-50267

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati

4.6
CVE-2026-38571

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands,

4.4
CVE-2025-36105

IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s

4.4
CVE-2026-28758

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t

4.4
CVE-2026-42408

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high

4.4
CVE-2026-59327

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string

4.3
CVE-2026-33003

Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co

4.3
CVE-2026-6598

A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function cre

4.3
CVE-2026-6796

A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor

4.3
CVE-2026-57287

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret

4.3
CVE-2026-55985

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o

4.3
CVE-2026-76376

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76377

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run action

4.3
CVE-2026-76378

In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permissi

4.3
CVE-2026-76379

In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions c

4.3
CVE-2026-76380

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run

4.3
CVE-2026-76381

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permissio

4.3
CVE-2026-76382

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76383

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with perm

4.3
CVE-2026-76384

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission

4.3
CVE-2026-76385

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could

4.3
CVE-2026-76386

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could ex

4.3
CVE-2026-76405

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S

4.0
CVE-2025-55717

A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7

3.7
CVE-2026-8026

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packag

3.3
CVE-2025-33081

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user

3.3
CVE-2026-16213

A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an un

3.2
CVE-2026-45362

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

2.1
CVE-2026-18591

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i

CVE-2025-14377

A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext

CVE-2025-59102

The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev

CVE-2025-59105

With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta

CVE-2024-9432

Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.  

CVE-2025-14815

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi

Frequently Asked Questions

What is CWE-312?

CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-312?

There are 230 CVE records associated with CWE-312 in our database. Of these, 16 are critical severity, 61 are high severity, and 95 are medium severity.

How can I protect against CWE-312 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.

Detect CWE-312 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.

Get Started